[New Thread 0x7f1f8dffb700 (LWP 22472)] Thread 13 "one_connection" received signal SIGSEGV, Segmentation fault. [Switching to Thread 0x7f1f9455e700 (LWP 22441)] Item_subselect::init (this=0x7f1f6c0436e8, select_lex=0x7f1f6c044240, result=0x7f1f6c040fd8) at /home/fuzzer/mariadb/sql/item_subselect.cc:124 124 parsing_place= (outer_select->in_sum_expr ? (gdb) bt #0 Item_subselect::init (this=0x7f1f6c0436e8, select_lex=0x7f1f6c044240, result=0x7f1f6c040fd8) at /home/fuzzer/mariadb/sql/item_subselect.cc:124 #1 0x000056047d215cbd in Item_allany_subselect::Item_allany_subselect (this=0x7f1f6c0436e8, thd=0x7f1f6c000db8, left_exp=, fc=, select_lex=0x7f1f6c044240, all_arg=true) at /home/fuzzer/mariadb/sql/item_subselect.cc:1724 #2 0x000056047ca92917 in all_any_subquery_creator (thd=thd@entry=0x7f1f6c000db8, left_expr=0x7f1f6c0446f8, cmp=0x56047ca92580 , all=true, select_lex=0x7f1f6c000db8) at /home/fuzzer/mariadb/sql/sql_parse.cc:9440 #3 0x000056047cf55998 in MYSQLparse (thd=0x7f1f6c0446f8, thd@entry=0x7f1f6c000db8) at /home/fuzzer/mariadb/sql/sql_yacc.yy:9767 #4 0x000056047ca8eaa9 in parse_sql (thd=thd@entry=0x7f1f6c000db8, parser_state=parser_state@entry=0x7f1f9455d3e0, creation_ctx=creation_ctx@entry=0x0, do_pfs_digest=true) at /home/fuzzer/mariadb/sql/sql_parse.cc:10327 #5 0x000056047ca6cbc1 in mysql_parse (thd=thd@entry=0x7f1f6c000db8, rawbuf=0x7f1f6c02d090 "CREATE PROCEDURE test_proc (id VARCHAR(255)) BEGIN DECLARE dt DATETIME(6) DEFAULT ROW(1, 2) = SOME(SELECT 1) = ALL(SELECT 1)", length=, parser_state=parser_state@entry=0x7f1f9455d3e0) at /home/fuzzer/mariadb/sql/sql_parse.cc:7867 #6 0x000056047ca68500 in dispatch_command (command=command@entry=COM_QUERY, thd=thd@entry=0x7f1f6c000db8, packet=packet@entry=0x7f1f6c00c599 "CREATE PROCEDURE test_proc (id VARCHAR(255)) BEGIN DECLARE dt DATETIME(6) DEFAULT ROW(1, 2) = SOME(SELECT 1) = ALL(SELECT 1)", packet_length=packet_length@entry=124, blocking=116) at /home/fuzzer/mariadb/sql/sql_parse.cc:1902 #7 0x000056047ca6dd03 in do_command (thd=thd@entry=0x7f1f6c000db8, blocking=100) at /home/fuzzer/mariadb/sql/sql_parse.cc:1415 #8 0x000056047cd667a4 in do_handle_one_connection (connect=, connect@entry=0x5604828384e8, put_in_cache=252) at /home/fuzzer/mariadb/sql/sql_connect.cc:1415 #9 0x000056047cd6638d in handle_one_connection (arg=arg@entry=0x5604828384e8) at /home/fuzzer/mariadb/sql/sql_connect.cc:1327 #10 0x000056047d57333f in pfs_spawn_thread (arg=0x560482773fd8) at /home/fuzzer/mariadb/storage/perfschema/pfs.cc:2198 #11 0x00007f1fbeae6609 in start_thread (arg=) at pthread_create.c:477 #12 0x00007f1fbe770353 in clone () at ../sysdeps/unix/sysv/linux/x86_64/clone.S:95